4 ms·
I meant no insult, but I see no other explanation. You're ignoring the letter of the law, ignoring context and nuance, making unfounded claims and providing li
by Zurrrrr 4y ago
I meant no insult, but I see no other explanation.
You're ignoring the letter of the law, ignoring context and nuance, making unfounded claims and providing links that don't support your points at all.
- jacquesm 4y ago> I meant no insult, but I see no other explanation. Then maybe you should consult the guidelines.
- Zurrrrr 4y ago> Then maybe you should consult the guidelines. And if someone is continuing to ignore facts and claim clearly false things as you were, what is the polite way to point that out?
- swores 4y agoI'll jump in here between the two of you and say that from my point of view it's you ignoring facts not jacquesm. I accept that if you believe jacquesm to be arguing in bad faith there's not a way to say that without it being a little bit rude, but I believe that description actually applies to your comments and not theirs. edit: your original claim- > GDPR tries to enforce its rules on servers outside of its territory. It's enforcing rules on data sent to/from people in the EU and the servers (not just servers ofc), i.e. on companies offering their services to people in the EU. If the companies don't wish to follow the laws of a specific country (or in this case, all EU countries), they're welcome to not provide services to those users. Since you seem to think the example they gave doesn't count because it's a Californian law not federal (not sure why that matters...), how about stuff like "The FTC engages with competition and consumer protection agencies in other countries to halt deceptive and anticompetitive business practices that affect U.S. consumers." ( https://www.ftc.gov/policy/international https://www.ftc.gov/policy/international ) which includes laws such as COPPA ( https://en.m.wikipedia.org/wiki/Children%27s_Online_Privacy_Protection_Act https://en.m.wikipedia.org/wiki/Children%27s_Online_Privacy_... ) Or let's say there's a country in Europe where hacking and ransomeware are completely legal, and a company in that country focussed their ransomeware efforts on attacking American companies. Would you argue that either the USA wouldn't care about that because it's outside their jurisdiction, or that they shouldn't care because it's outside their jurisdiction?
- PrimeMcFly 4y agoNo worries at all, I don't take that personally, but may I ask what facts you think I am ignoring? The facts are as follows: 1. GDPR asserts extraterritorial jurisdiction. This is clearly documented and is within the text of the act itself. 2. This is unprecedented. There is no other law from any (lets say first world) country that asserts extraterritorial jurisdiction to anywhere even close to the GDPR. I've provided links for both of these claims. jacquesm is arguing against both of those facts, claiming they are not in fact true, and linking to US laws trying to state that are the same thing, when they are not even close. > It's enforcing rules on data sent to/from people in the EU and the servers (not just servers ofc), i.e. on companies offering their services to people in the EU. Quoting from an earlier link I posted: "Let’s say for example that you are a Chinese web shop with a website that is available in German, French and English as well. You also process multiple orders a day from individuals within the EU and ship your products to them. This will make you fall in the scope of the GDPR, even though you have no establishment in the EU and are not performing any data processing activities within the EU." The point is that that Chinese web shop can provide services to EU citizens, and the EU has no way of enforcing any aspect of the GDPR on that Chinese webs hop, and I'm pretty sure China would be the first to tell you the GDPR does not apply within its borders. > If the companies don't wish to follow the laws of a specific country (or in this case, all EU countries), they're welcome to not provide services to those users. In this case, the company could be following the laws in their home country, and be in violation of the GDPR just because an EU citizen bought something from them. In this case, the EU is responsible for blocking the website, rather than the website needing to be in compliance with the GDPR.
- swores 4y ago> "This is unprecedented. There is no other law from any (lets say first world) country that asserts extraterritorial jurisdiction to anywhere even close to the GDPR." Here's an example of that not being true: https://en.wikipedia.org/wiki/Megaupload https://en.wikipedia.org/wiki/Megaupload Or a more recent example that's related to financial/fraud regulations rather than copyright law, look at the FTX / Sam Bankman-Fried situation. Being registered in the Bahamas didn't make what FTX was doing to US customers any less illegal in the eyes of the US justice system. Or, I mentioned COPPA earlier, and that's been enforced at least once against a Chinese company - https://www.ftc.gov/business-guidance/blog/2019/02/largest-ftc-coppa-settlement-requires-musically-change-its-tune https://www.ftc.gov/business-guidance/blog/2019/02/largest-f...